Usabilitydynamics / WP-Invoice
7 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-1617 | WP-Invoice <= 4.3.1 - Stored Cross-Site Scripting via CSRF | MEDIUM | 6.1 | Jan 16, 2024 |
| CVE-2016-11011 | The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation. | MEDIUM | 6.5 | Sep 20, 2019 |
| CVE-2016-11010 | The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates. | MEDIUM | 5.3 | Sep 20, 2019 |
| CVE-2016-11009 | The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates. | MEDIUM | 5.3 | Sep 20, 2019 |
| CVE-2016-11008 | The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates. | MEDIUM | 5.3 | Sep 20, 2019 |
| CVE-2016-11007 | The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval. | MEDIUM | 5.3 | Sep 20, 2019 |
| CVE-2016-11006 | The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes. | MEDIUM | 5.3 | Sep 20, 2019 |
Showing 1 to 7 of 7 CVEs